🏠 All tools

← Lock It DownEspaΓ±ol

Secure Your Accounts

Almost every account hack traces back to the same few weaknesses. Close them and you've shut the door on the overwhelming majority of attacks β€” no technical skill required.

General security information β€” not a guarantee or professional advice. The exact menus and wording differ by service and change over time, so take the steps as the idea and find the current option in each app's settings.

You don't have to secure everything perfectly. Account safety follows a brutal 80/20 rule: a handful of habits stop almost everything, and skipping them leaves you wide open no matter what else you do. The three that matter most are a unique password for every account (with a manager doing the remembering), a second factor turned on, and your email locked down hardest of all β€” because whoever controls your email can reset their way into everything else you own.

The one idea: protect your email first (it's the master key that resets every other account), give every account a unique password via a password manager, and turn on two-factor authentication. Those three block the vast majority of takeovers.

Your email is the master key

Think about what happens when you forget a password anywhere: the reset link goes to your email. That means your inbox isn't just another account β€” it's the skeleton key to your bank, your shopping, your social media, everything. Whoever owns your email owns your digital life.

Stop reusing passwords β€” let a manager remember

Reuse is the number-one cause of account takeover

When any one site gets breached, criminals take those leaked email-and-password pairs and try them everywhere else (it's automated, and it's called credential stuffing). One reused password can unlock a dozen of your accounts.

A password manager makes unique passwords effortless

It generates and stores a different strong password for every site, and fills them in for you. You remember one strong master password; it handles the rest. The ones built into your browser or phone are a fine place to start, and dedicated apps do more.

Length beats complexity. A long passphrase β€” four or five random words you can picture β€” is both stronger and easier than "P@ssw0rd!". Make your master password long, unique, and something you've never used anywhere else.

Turn on two-factor (2FA)

Two-factor means a second step beyond your password β€” so even if your password leaks, an attacker still can't get in. It's the single biggest upgrade after unique passwords.

Even better, where offered: passkeys. A passkey logs you in with your face, fingerprint, or device PIN instead of a password, and it can't be phished or reused. When a service offers one, it's the most secure option going.

Spot a takeover attempt

Never share a verification code. A real company will never call or message asking you to read back a login or "verification" code. Anyone who does is trying to break into your account right now β€” that code is the second factor they're missing.

The other classic move is a fake "unusual sign-in" or "your password was changed" alert with a link that leads to a convincing fake login page. Don't click it β€” go to the site directly through your own bookmark or app and check there. (Spotting these is the heart of the Hold Your Own scam-defense kit.)

A 20-minute starting plan

  1. Set up a password manager (browser, phone, or a dedicated app) and pick one strong master passphrase.
  2. Fix your email first β€” give it a new unique password and turn on 2FA.
  3. Then your bank and main accounts β€” unique password + 2FA on each, a few at a time.
  4. Save your backup codes somewhere you won't lose them.
  5. Sign out everywhere unfamiliar β€” most big accounts have a "where you're logged in" list; boot anything you don't recognize.

Account-security checklist

Tick what's done.

The close

Digital security sounds exhausting, but the part that matters isn't. Three habits β€” protect your email, use a password manager, turn on two-factor β€” quietly defeat the attacks that actually happen to ordinary people. Set them up once, mostly in an afternoon, and you go from "one leaked password away from chaos" to a genuinely hard target. You don't need to be paranoid or technical. You need unique passwords, a second factor, and the instinct to never hand over a code. Lock those down, and the rest is details.

Free and public domain (CC0) β€” copy it, translate it, share it. No accounts, no tracking; it runs entirely in your browser, and nothing you tick is saved or sent. General security guidance, not a guarantee; menus vary by service and change over time, so find the current setting in each app.

Last reviewed: June 2026. This is general information that can age β€” verify time-sensitive specifics (laws, numbers, programs, app menus) against current official sources.